LimeSurvey 社区版 7.0.5 在问卷配额创建流程中存在一个存储型跨站脚本(Stored XSS)漏洞。一个拥有创建和管理自己问卷权限的低权限认证用户,可以在配额消息(quota message)中植入恶意 JavaScript 代码。 该问题影响 LimeSurvey 7.0.5 版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| LimeSurvey | LimeSurvey | 7.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-15973 | 8.4 HIGH | LimeSurvey 7.0.5 - Stored XSS in Survey Menu Entries |
| CVE-2026-63360 | 7.4 HIGH | LimeSurvey Community Edition 7.0.5 - Reflected XSS in user activation confirmation endpoin |
| CVE-2026-65930 | 4.8 MEDIUM | LimeSurvey Community Edition 7.0.5 - Stored XSS in replacement-fields |
No comments yet